Feature to track data about hardware wallets and installed applications has been discovered in Ledger Live
The device activates authentication when interacting with applications
28.12.2023 - 08:57
168
2 min
0
What’s new? Ledger Live software for Ledger hardware crypto wallets tracks data about users and applications installed on their devices, a developer under the nickname @rektbuildr reported on his page in X, based on the results of the program’s code research. According to him, Ledger Live activates authentication when interacting with applications installed on the wallet, which prevents anonymous use of the device.
What else is known? The developer said that device authentication is embedded in the listApps subroutine, and when you try to disable remote tracking, the program starts working incorrectly. Thus, Ledger captures every time the device is turned on and knows what applications are running on it.
“Hardware wallets should work 100% offline. No phoning back anything at all. It’s crazy that we have to be discussing this in 2023 but here we are,” @rektbuildr emphasized.
He also noted that Ledger recently implemented a private key recovery feature, parts of which are deposited with third parties, and wondered how the company can ensure that this data is protected from being read by unauthorized parties.
The developer emphasized that he does not want to spread panic (FUD), but also urged not to upgrade Ledger Live to a newer version if users are happy with the current one.
He also believes Ledger should allow experienced users to work with fully standalone devices by making the ability to use Ledger Live optional.
Earlier this month, hackers exploited the Ledger Connect Kit Javascript library to connect websites to Ledger’s hardware wallets. The company patched the vulnerability and assured that the attack did not affect the integrity of Ledger or Ledger Live hardware and only affected third-party decentralized applications (DApps) that used the library.
Ledger later reported that users lost $600 000 due to the blind signing mechanism vulnerability. The company pledged to reimburse the losses and replace the mechanism of interaction with DApps with a fully transparent one by June 2024.
Useful material?
Market
The company’s unrealized profits from investing in its first cryptocurrency approached $14 billion
Nov 19, 2024
Incidents
The search, the reason for which was not announced, took place a week after the election, the results of which Polymarket users predicted quite accurately
Nov 14, 2024
Market
Analysts point to the growing popularity of the first cryptocurrency as a safe haven asset
Nov 13, 2024
Market
The product will begin trading on the Swiss Exchange on November 19
Nov 12, 2024
Market
The company’s unrealized profits from investing in the first cryptocurrency approached $13 billion
Nov 12, 2024
Market
The company predicts that the rate of the first cryptocurrency will grow to $200 000 by the end of next year
Nov 11, 2024